Full Report
Quantum computers leverage qubits (the quantum equivalent of classical computer bits) to solve specific problems significantly faster than classical computers. However, the emergence of quantum computers could undermine the cryptography (e.g., encryption) that federal agencies use to secure their systems. Today’s quantum computers cannot yet break this cryptography. But a future quantum computer of sufficient…
Analysis Summary
# Regulation/Compliance: GAO Post-Quantum Cryptography (PQC) Transition Framework
## Overview
This requirement addresses the looming threat of Cryptographically Relevant Quantum Computers (CRQCs), which are expected to be capable of breaking current encryption standards by the 2030s. The Government Accountability Office (GAO) has established an evaluation framework to ensure federal agencies transition their systems to Post-Quantum Cryptography (PQC) to prevent unauthorized data decryption and system compromise.
## Key Details
- **Issuing Authority:** Government Accountability Office (GAO) & Office of Management and Budget (OMB)
- **Effective Date:** October 2026 (Reporting Date)
- **Jurisdiction:** United States Federal Agencies
- **Status:** In Effect (Active Oversight)
## Requirements
### Mandatory Requirements
1. **PQC Transition Planning:** Agencies must establish a formal plan to migrate existing systems to post-quantum algorithms.
2. **Cryptographic Inventory:** Identification of all systems currently utilizing vulnerable classical cryptography.
3. **OMB Compliance:** Adherence to the specific PQC transition guidance and evaluation practices issued by the OMB.
### Recommended Practices
1. **Adoption of GAO Evaluation Framework:** Implementation of the three key GAO practices for PQC preparation.
2. **Early Data Protection:** Prioritizing the encryption of sensitive data that may be subject to "harvest now, decrypt later" attacks by adversaries.
## Affected Organizations
- **Industries:** All Federal Executive Branch agencies; critical infrastructure sectors interacting with federal systems.
- **Organization Size:** Large-scale federal entities (24 major agencies specifically audited).
- **Geographic Scope:** United States federal government operations.
## Compliance Timeline
- **2024–2026:** GAO audit period assessing agency readiness.
- **October 07, 2026:** Publication of GAO-27-108740, highlighting that none of the 24 selected agencies have fully met PQC transition requirements.
- **2030s (Estimated):** Projected emergence of CRQCs; the window for full cryptographic migration.
## Implementation Guidance
### Assessment Phase
- **Inventory Discovery:** Identify hardware, software, and firmware using public-key cryptography (e.g., RSA, Diffie-Hellman).
- **Risk Evaluation:** Assess the sensitivity of data to determine which systems require the most urgent migration.
### Implementation Phase
- **Cryptographic Agility:** Update systems to support the easy replacement of cryptographic algorithms.
- **Phased Migration:** Begin implementing NIST-approved post-quantum algorithms into new and high-priority systems.
### Validation Phase
- **GAO Audit Review:** Agencies must undergo evaluation against the GAO’s three-practice framework to verify transition progress.
## Technical Requirements
- **Transition to PQC:** Moving from classical qubits-vulnerable algorithms to quantum-resistant standards.
- **Authentication Safeguards:** Updating systems that ensure the authenticity of users to prevent CRQC-enabled unauthorized access.
## Penalties & Enforcement
- **Fines:** Not applicable to federal agencies; however, budgetary impacts may occur.
- **Other Consequences:** Increased vulnerability to state-sponsored actors (PRC/Russia); risk of total data compromise; congressional oversight hearings.
- **Enforcement:** The GAO performs audits and issues public reports on non-compliance; OMB issues management directives to agency heads.
## Related Standards
- **NIST PQC Standards:** The underlying algorithms (e.g., ML-KEM, ML-DSA) that agencies are expected to adopt.
- **Quantum Computing Cybersecurity Preparedness Act:** The legislative driver for these federal actions.
## Resources
- **Official Documentation:** [gao.gov/products/gao-27-108740](https://www.gao.gov/products/gao-27-108740)
- **Guidance Documents:** OMB Memorandum on Migrating to Post-Quantum Cryptography.
## Practical Recommendations
- **Immediate Action:** Agencies should assign a dedicated lead for PQC transition and begin a comprehensive cryptographic audit.
- **Data Prioritization:** Focus on protecting long-life data that remains sensitive for 10+ years, as this is the primary target for current data harvesting.